CVE-2025-21045
- EPSS 0.02%
- Veröffentlicht 10.10.2025 06:33:03
- Zuletzt bearbeitet 09.01.2026 18:11:58
Insecure storage of sensitive information in Galaxy Watch prior to SMR Oct-2025 Release 1 allows local attackers to access sensitive information.
CVE-2025-21004
- EPSS 0.01%
- Veröffentlicht 08.07.2025 10:34:34
- Zuletzt bearbeitet 20.01.2026 14:41:30
Improper verification of intent by broadcast receiver in System UI for Galaxy Watch prior to SMR Jul-2025 Release 1 allows local attackers to power off the device.
CVE-2025-20998
- EPSS 0.02%
- Veröffentlicht 08.07.2025 10:34:27
- Zuletzt bearbeitet 20.01.2026 14:42:28
Improper access control in SamsungAccount for Galaxy Watch prior to SMR Jul-2025 Release 1 allows local attackers to access phone number.
CVE-2025-20997
- EPSS 0.02%
- Veröffentlicht 08.07.2025 10:34:26
- Zuletzt bearbeitet 20.01.2026 15:09:19
Incorrect default permission in Framework for Galaxy Watch prior to SMR Jul-2025 Release 1 allows local attackers to reset some configuration of Galaxy Watch.
CVE-2025-20986
- EPSS 0.02%
- Veröffentlicht 04.06.2025 04:56:16
- Zuletzt bearbeitet 02.02.2026 18:14:45
Improper access control in ScreenCapture for Galaxy Watch prior to SMR Jun-2025 Release 1 allows local attackers to take screenshots.
CVE-2025-20984
- EPSS 0.02%
- Veröffentlicht 04.06.2025 04:56:14
- Zuletzt bearbeitet 02.02.2026 18:14:48
Incorrect default permission in Samsung Cloud for Galaxy Watch prior to SMR Jun-2025 Release 1 allows local attackers to access data in Samsung Cloud for Galaxy Watch.
CVE-2025-20956
- EPSS 0.03%
- Veröffentlicht 07.05.2025 08:24:07
- Zuletzt bearbeitet 15.01.2026 16:19:11
Improper export of android application components in Settings in Galaxy Watch prior to SMR May-2025 Release 1 allows physical attackers to access developer settings.
CVE-2025-20946
- EPSS 0.12%
- Veröffentlicht 08.04.2025 04:50:11
- Zuletzt bearbeitet 27.01.2026 17:55:09
Improper handling of exceptional conditions in pairing specific bluetooth devices in Galaxy Watch Bluetooth pairing prior to SMR Apr-2025 Release 1 allows local attackers to pair with specific bluetooth devices without user interaction.
CVE-2025-20939
- EPSS 0.06%
- Veröffentlicht 08.04.2025 04:49:41
- Zuletzt bearbeitet 27.01.2026 17:54:54
Improper authorization in wireless download protocol in Galaxy Watch prior to SMR Apr-2025 Release 1 allows physical attackers to update device unique identifier of Watch devices.
CVE-2025-20945
- EPSS 0.09%
- Veröffentlicht 08.04.2025 04:40:00
- Zuletzt bearbeitet 27.01.2026 17:55:02
Improper access control in Galaxy Watch prior to SMR Apr-2025 Release 1 allows local attackers to access sensitive information of Galaxy watch.